CWE-24— Path Traversal: '../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.— MITRE CWE catalog
124 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-24page 1 of 3
- CVE-2025-27920CRITICALCVSS 7.2EG 9.8⚠ KEV2025-05-05
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially lea…
- CVE-2026-39813CRITICALCVSS 9.8EG 9.82026-04-14
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
- CVE-2023-7134CRITICALCVSS 9.8EG 9.82023-12-28
A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument page leads to path traversal: '../filedir'. The attack ma…
- CVE-2023-7058CRITICALCVSS 9.8EG 9.82023-12-22
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument page leads to path traversal: …
- CVE-2022-38129CRITICALCVSS 9.8EG 9.82022-08-10
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to…
- CVE-2026-49103CRITICALCVSS 9.4EG 9.42026-05-27
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
- CVE-2025-61318CRITICALCVSS 9.1EG 9.12025-12-08
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for delet…
- CVE-2023-6699CRITICALCVSS 9.1EG 9.12024-01-11
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read th…
- CVE-2023-6900CRITICALCVSS 9.1EG 9.12023-12-17
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path…
- CVE-2025-54769HIGHCVSS 8.8EG 8.82025-07-29
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve r…
- CVE-2025-53513HIGHCVSS 8.8EG 8.82025-07-08
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an atta…
- CVE-2024-23657HIGHCVSS 8.8EG 8.82024-08-05
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined wit…
- CVE-2021-33036HIGHCVSS 8.8EG 8.82022-06-15
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 …
- CVE-2023-1398HIGHCVSS 6.3EG 8.82023-03-14
A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/upload. The manipulation leads to path traversal: '../filedir'. The attack can be laun…
- CVE-2025-60344HIGHCVSS 8.6EG 8.62025-10-21
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Su…
- CVE-2026-97730HIGHCVSS 8.5EG 8.52026-09-25
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To expl…
- CVE-2026-40318HIGHCVSS 8.5EG 8.52026-04-16
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path bound…
- CVE-2023-52076HIGHCVSS 8.5EG 8.52024-01-25
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing a…
- CVE-2026-66140HIGHCVSS 7.8EG 8.42026-07-24
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
- CVE-2023-53691HIGHCVSS 8.3EG 8.32025-10-22
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025.
- CVE-2026-34151HIGHCVSS 8.2EG 8.22026-07-07
XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix whe…
- CVE-2025-63298HIGHCVSS 8.2EG 8.22025-10-30
A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting…
- CVE-2026-41082HIGHCVSS 7.8EG 7.82026-04-16
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
- CVE-2026-46687HIGHCVSS 7.7EG 7.72026-07-16
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists…
- CVE-2026-105314HIGHCVSS 7.5EG 7.52026-10-05
Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interp…
- CVE-2026-103088HIGHCVSS 7.5EG 7.52026-09-30
Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened …
- CVE-2026-28427HIGHCVSS 7.5EG 7.52026-03-04
OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request…
- CVE-2025-67364HIGHCVSS 7.5EG 7.52026-01-07
fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their …
- CVE-2025-51661HIGHCVSS 7.5EG 7.52025-11-19
A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from use…
- CVE-2025-59049HIGHCVSS 7.5EG 7.52025-09-10
Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach presented in the documentation page, where the server filename is generated via templating…
- CVE-2025-48050HIGHCVSS 7.5EG 7.52025-05-15
In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in…
- CVE-2024-22079HIGHCVSS 7.5EG 7.52024-03-20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.
- CVE-2022-36065HIGHCVSS 7.5EG 7.52022-09-06
GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, attackers can register new accounts and upload files to arbitrary directories within the cont…
- CVE-2020-7882HIGHCVSS 7.5EG 7.52021-11-22
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
- CVE-2019-25087HIGHCVSS 5.3EG 7.52022-12-27
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri l…
- CVE-2014-125033HIGHCVSS 3.5EG 7.52023-01-02
A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/controllers/uploaded_files_controller.rb. The manipulation with the input ../../../etc/passwd…
- CVE-2026-22810HIGHCVSS 7.3EG 7.32026-05-18
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The …
- CVE-2025-57618HIGHCVSS 7.3EG 7.32025-10-14
A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the server. By leveraging this vulnerability, it is possible to access the application's configuration files, which contain …
- CVE-2023-1800HIGHCVSS 7.3EG 7.32023-04-02
A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to p…
- CVE-2026-14947HIGHCVSS 7.2EG 7.22026-08-20
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve …
- CVE-2021-26725HIGHCVSS 7.2EG 7.22021-02-22
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3…
- CVE-2026-92533HIGHCVSS 7.1EG 7.12026-10-07
Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to acce…
- CVE-2022-1743MEDIUMCVSS 6.8EG 6.82022-06-24
The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by specially crafted election definition files. An attacker could leverage this vulnerability to spread malicious code to ImageCa…
- CVE-2026-73573MEDIUMCVSS 6.5EG 6.52026-08-13
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vul…
- CVE-2026-44942MEDIUMCVSS 6.5EG 6.52026-06-18
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with conten…
- CVE-2026-33431MEDIUMCVSS 6.5EG 6.52026-04-20
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path …
- CVE-2026-21857MEDIUMCVSS 6.5EG 6.52026-01-07
REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backu…
- CVE-2025-57563MEDIUMCVSS 6.5EG 6.52025-10-14
A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files.
- CVE-2025-1588MEDIUMCVSS 6.5EG 6.52025-02-23
A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path …
- CVE-2022-20656MEDIUMCVSS 6.5EG 6.52024-11-15
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker …
Map vulnerabilities like CWE-24 to your infrastructure
EchelonGraph correlates every CVE — across CWE-24 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →